Five/Nine/Fourteen-Eyes, explained.
Three overlapping intelligence-sharing agreements quietly decide which governments can read each other's traffic — and by extension, which VPNs have to hand your data over on request. Here's what they actually are, what they actually share, and why your VPN's jurisdiction is a feature, not a footnote.
What the alliances actually are
The Five Eyes (FVEY) trace back to the 1946 BRUSA Agreement and the 1948 UKUSA Agreementbetween the United States and the United Kingdom. They formalized a wartime signals-intelligence (SIGINT) partnership that had grown out of Bletchley Park's wartime work and continued through the Cold War. Canada, Australia, and New Zealand joined over the following years, and the alliance has operated continuously ever since.
Two wider rings — Nine Eyes and Fourteen Eyes — add a second and third tier of cooperating nations. The outer rings are not as binding as FVEY (no standing treaty, more ad-hoc), but they still share bulk metadata, participate in joint task forces, and routinely defer requests to cooperating agencies when their own domestic law pushes back.
Why it matters for consumers
When a member-state intelligence agency collects signals on its own citizens, those signals can be shared — and queries retargeted — across alliance partners using legal wrappers like UKUSA's “third-party rule.” A warrant that wouldn't hold up in a domestic court can still get data a friendly partner already has. In the consumer VPN world, that means:
- A “strict no-logs” claim from a provider headquartered inside any of these 14 jurisdictions is only as good as that jurisdiction's enforcement — and the practical enforcement is shaped by whether the agency can ask a partner to ask.
- Server locations don't rescue you. A provider based in Fourteen Eyes country can be legally compelled to log a user who's physically connecting through Iceland or Panama.
- The most famous public trigger for the modern debate is the 2013 Snowden disclosures — particularly the Tempora (GCHQ) and XKeyscore (NSA) programs, which demonstrated that allied agencies share raw internet backbone data in near-real-time.
The jurisdictional roll-up
Source agencies for each tier — every member below can request data from (or through) the others, so a single VPN operator knows who can read their logs.
| Alliance | Members | Primary SIGINT agency |
|---|---|---|
| Five Eyes | United States, United Kingdom, Canada, Australia, New Zealand | NSA · GCHQ · CSE · ASD · GCSB |
| Nine Eyes | Five Eyes + Denmark, France, Norway, Netherlands | + PET (DK) · DGSE / DGSI (FR) · NSM (NO) · AIVD / MIVD (NL) |
| Fourteen Eyes | Nine Eyes + Germany, Belgium, Italy, Spain, Sweden | + BND (DE) · VSSE (BE) · AISE / AISI (IT) · CNI (ES) · FRA (SE) |
SpinGate's stance
SpinGateroutes traffic through data-retention-light, crypto-friendly jurisdictions — and we publish what we don't keep so you don't have to take our word for the things we do. Concretely, that means:
- Operators are domiciled outside the Fourteen-Eyes ring so a single legal request can't reach the whole alliance's SIGINT apparatus.
- Sessions are paid in crypto and issued per-use — there's no monthly identity to map back to a person, no card statement to subpoena.
- We treat “no logs” as an architectural claim, not a marketing line: the connection metadata that typically feeds an alliance request simply isn't generated.
When you evaluate any provider, ask three questions: where is the operator incorporated? who owns the servers? what logs exist to hand over?If they can't answer those plainly, treat their jurisdiction story as a guess.
Read the digital-sovereignty pillar → for the broader framework.